Skip to main content
Question

Simple(st) configuration deployment (new Mac admin)

  • July 29, 2026
  • 8 replies
  • 61 views

Forum|alt.badge.img+1

Hi there - I’m new here so if I’m somehow off-target with this post, please let me know! I looked around for a Welcome message with guidelines, but had no luck. Sorry if I misunderstand anything. Here is what I’ve come to ask:

What is the simplest effective way to properly secure 1-3 Macbooks? The scale is small but security requirements happen to be high (imagine a law firm, for example). I need both a professional configuration, which I’ll tweak for our purposes, and a deployment tool, but an entire MDM solution is way too much.

 

Some background: I’m an experienced admin on other platforms, I’ve lightly used and helped out people with Macs for a long time but I’m new to actual, professional Mac adminsitration. Now I have just a few Macbooks, one to start. To narrow scope, I’m not worried about configuring or locking down user behavior, productivty, or updates and management (for this purpose). I need to lock down system and network behavior, including protecting identity (so no iCloud, Apple ID, etc.). Here’s what I’ve considered:

 *  DIY manually configure Settings GUI: Inevitably there are issues not visible to consumers (for whom Settings GUIs are designed), and also due to my inexperience with the platform, DIY is a bad idea.

 *  DIY .mobileconfig file: Again, I don’t know the platform well enough to do this properly. I’m not even sure a .mobileconfig file is the correct or only component required.

 *  Apple Configurator: Is this reasonably simple and effective for someone new to it? Also, I’ll still need a configuration to deploy.

 *  profiles CLI: Same questions as Apple Configurator.

 *  mSCP; Possibly a source for a configuration? Can that be deployed with some simple tool (Configurator? profiles?)? Is it reasonable to think I learn it and deploy it relatvely efficiently? Can I just tweak the MacOS baseline, download, and deploy? (Just fantasizing for a moment!)

 *  Apple Business: Seems like a lot of overhead, and seems to permanently associate user (or organization) with the laptop. The users don’t want an Apple ID or account, and no iCloud, etc. Also, does it have a baseline security config?

 *  Jamf Now: Similar concerns to Apple Business, though I know less about Jamf Now: How much info do I need to give Jamf in order to use it?

 

 

Thank you very much in advance! We would pay a reasonable amount for these things but as always in a small organization, budget and time are tight.

8 replies

LysetteB
Forum|alt.badge.img+17
  • Community Manager
  • July 29, 2026

@jamer you know, that is a great idea to add a ‘how-to’ approach for new members first posts! Thanks for the suggestion and welcome to Jamf Nation 😊 I’ve no doubt one of our top members can help with your query ​@mvu ​@Chubs ​@mattjerome ​@MusicCityMac ​@ThomM 💡


ThomM
Forum|alt.badge.img+22
  • Jamf Heroes
  • July 29, 2026

Apple has really gone in the direction of needing an MDM in order to truly lock down the things it sounds like you’re looking to do.

While you can manually create and install .mobileconfigs, more and more of the things they manage require that they be installed via an MDM rather than by hand.  You may get it working now, but there’s no telling what a future macOS version will break on you. For example we used to deploy a wired network 802.1x .mobileconfig by hand before we had Jamf more widely managing our Division’s Macs.  Worked great, but now if you tried to install that same .mobileconfig manually it would fail.  Works a charm when an MDM installs it though.

It’s also probably worth your while to at least get Apple Business set up so you can leverage automated device enrollment into whatever MDM option you choose. I’m aware that Apple Business now offers some device management functionality that Apple School Manager doesn’t, but being at a university we’re an ASM house so I haven’t had hands on AB as a management solution.

I know Jamf Now lets you manage up to 3 devices for free, then it’s a per device subscription over that. There are also some open source MDM solutions out there, but I don’t have experience with them.  Either way, an MDM solution is going to need to be connected to an AB or ASM instance to really do things smoothly.


Forum|alt.badge.img+1
  • Author
  • New Contributor
  • July 29, 2026

Thank you @LysetteB! My greatest uncertainty is how much this forum is for Jamf only, and how much for all Apple admin issues with Jamf generously hosting. I hope I got it right.

 

I should add to my post above:

 *  Lockdown mode: This doesn’t seem intended for my use case but maybe it does the job and is still usable? Is it a complete security solution or only for specific needs? Can I modify settings as needed? Is it functional for office workers - we don’t need lots of features, but we need to be able to participate in Zoom calls, for example.


Chubs
Forum|alt.badge.img+26
  • Jamf Heroes
  • July 29, 2026

So Apple Business is a necessity for what you want - “corp” managed devices.

With that being said, Jamf Now will do what you want without requiring a managed apple account (unlike Apple Business’ in-built MDM).  Having individual mobileconfigs for devices deployed via iMazing, Configurator, or some other tool is not recommended mainly because of Apple’s declarative approach moving forward (see: MacOS Golden Gate).

I’m going to put my money on Jamf Now for your use case - especially due to the “requirements” that you have.  If you need assistance, please feel free to reach out.


Forum|alt.badge.img+1
  • Author
  • New Contributor
  • July 29, 2026

Thanks @ThomM and @Chubs!

I’ve been away to study up on Apple’s declarative management [1]. Can Jamf Now be used for deployment and then disconnected? Also, is there a professionally designed security config available, or at least does Jamf Now have a checklist/UI with the essential options?

 

Hosted MDM has been a wonderful development for many purposes, but they are challenging for these needs: Several hosted MDMs have become attack vectors - their usefulness makes MDMs perfect for the purpose, providing great remote visibility and capability. Breach one MDM vendor and you own organizations all over the world. Also I’ve seen so many vendors of all types suddenly change policies and start collecting client information that we don’t trust them with the capability, and of course we can’t easily switch MDM vendors (many ‘anonymize’ the data but that’s generally ineffective, especially against LLM capabilities).

(It seems like declarative management could still be run locally (serverless) if there were simple tools. It shifts some MDM operations from server to device; the local tools might only need to generate simple delcarations, rather than .mobileconfig files, and apply them; it could  manage compliance, now done device-side, and do asset management via a local status channel (or even via 127.0.0.1). There’s a lot I don’t know, so maybe that wouldn’t work with the mechanics of declarative management.)

 

[1] This video was a good quick intro for me: https://developer.apple.com/videos/play/wwdc2021/10131/


LysetteB
Forum|alt.badge.img+17
  • Community Manager
  • July 30, 2026

@jamer totally understandable! This is very much an open Apple community for anyone to learn and jump in. It’s largely focused on Jamf but any Apple focussed questions are welcome! For example we host a Professional Development Series that anyone in Jamf Nation is welcome to join and it’s not Jamf product related. You’re welcome to get involved! 


mvu
Forum|alt.badge.img+22
  • Jamf Heroes
  • July 30, 2026

Curious, are the 1-3 MacBooks mostly in a local office, with some regional traveling? Or will they be in completely different states?

I get your question. You’re in a small scale, so there’s a “DIY” mentality to save up on costs.

I’d say still shop around to see what the costs are out there. Do you see the law firm expanding on the 1-3 MacBooks? That would alter deployment decisions, for me.

Either way, if security is paramount to your devices, look into CIS Benchmarks or other security benchmarks. You could do it yourself with Jamf Compliance Editor (free) in tandem with Apple Configurator or with your future MDM.

Jamf Pro rolled out a Compliance feature, which is nice because it reports, audits, and deploys with a few easy clicks. Set it. Forget it. (But still test it.)

These two training resources should help you with new MDM knowledge for Jamf. Could help you translate into other MDMs, and help you with your decisions.

• https://www.jamf.com/training/100-course/
• https://trainingcatalog.jamf.com


Forum|alt.badge.img+1
  • Author
  • New Contributor
  • July 30, 2026

Thank you ​@mvu :

Curious, are the 1-3 MacBooks mostly in a local office, with some regional traveling? Or will they be in completely different states?

Local office plus traveling.

 

Do you see the law firm expanding on the 1-3 MacBooks? That would alter deployment decisions, for me.

I’m not even sure we’ll have 3. I agree - and if I knew we’d have just 10 then I’d want proper MDM of some sort. I don’t really have time for any of this before the first one needs to be deployed and that creates a headache now (fit in some sort of management solution) and/or later (redeploying the first one). Also, it’s not really a law firm, sorry if that was confusing; I meant that as an example of an organization with small scale and high security needs.

I will check out your recommendations. That Jamf Compliance Editor is built on mSCP is great - a combination of a professionally designed configuration and a tool to deploy it. I’ll also look at what CIS has to offer; I’d forgotten about them.

 

 

 I get your question. You’re in a small scale, so there’s a “DIY” mentality to save up on costs.

Yes, it’s so different than even mid-sized organizations. The resources just don’t exist. If we’re going to have a Mac platform MDM expert, it’s me, stopping everything else I’m doing to learn, deploy, maintain, operate …. Even coming up with formal requirements is not realistic. And yet some needs can be the same as anyone else.